Add link the Security Guidance from CFRG
@hhalpin is already working on this.
Since Sep 12, 2016.
- Dominant language
- HTML
- Stars
- 294
- Forks
- 78
- PR merge metrics
- No merged PRs in 30d
Description
Quite a while back we got a formal objection from Rich Salz (https://www.w3.org/Bugs/Public/show_bug.cgi?id=25607) over lack of guidance for developers. Since then, we made a document (https://www.ietf.org/archive/id/draft-irtf-cfrg-webcrypto-algorithms-00.txt) and got it accepted at CFRG. I'd like to add, as per previous email, a reference to the CFRG document to the spec to get over the Formal Objection. I'm working with INRIA (Karthik Bharagavan and Graham Steel) to have the document updated by end of the week to take into account any new attacks over the last year.
The sentence (from https://lists.w3.org/Archives/Public/public-webcrypto/2015Oct/0040.html) that would explain this informative note is:
"Note that the security properties of particular algorithms in this specification are liable to change. Detailed questions can be asked to the IRTF CFRG, who are maintaining a document that outlines security guidelines for algorithms and key sizes as well as reference to the wider cryptographic literature."
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.